2 Answers
2

Turns out the "shadowMax"-attribute being set was causing the NT_STATUS_PASSWORD_MUST_CHANGE error. By removing the mentioned attribute in the LDAP objects of the specific users having the problem, those users were able to log in.

Using OpenLDAP as the backend and trying to mount it from a Linux workstation. The "Users & group policy manager" sounds rather AD related; so that shouldn't apply here. Worth mentioning is that I as mentioned have tried to change the password of the user, and the "sambaPwdMustChange" attribute of the LDAP user is set to a timestamp in the future.
–
ALanderMay 28 '12 at 5:41